Document Overview & Enforceability
This document is published under the engineering and governance authority of Yash Kumar Jha, Founder & Chief Solutions Architect of New Age Technology. Please review all terms, data privacy practices, and SLA specifications carefully.
Notice Regarding Roles & Processing Scope
This Privacy Policy outlines how NEW AGE TECHNOLOGY ("Company", "we", "us", or "our") handles personal data across our software platforms, custom engineering services, and messaging solutions. Depending on whether you interact with us as a direct client, a visitor, or via an API client integration, we operate as either a Data Controller or a Data Processor/Service Provider.
1. Scope & Application
This policy governs personal data collected and processed through:
- Our Software-as-a-Service (SaaS) web platforms, developer portals, dashboard interfaces, and mobile applications.
- Custom software development, web development, cloud architecture, and technical consulting contracts.
- WhatsApp Business API connectors, messaging gateway middleware, webhooks, and communication automation tools.
- Our public marketing websites, support portals, client ticketing consoles, and communication channels.
2. Information We Collect
2.1. Account & Direct Client Data (Data Controller)
When you register for our SaaS products, request a quote, or contract our engineering services, we collect:
- Identity & Contact Details: Full name, corporate email address, phone number, company name, billing address, tax identification numbers (e.g., GSTIN/VAT/EIN).
- Authentication & Security Credentials: Passwords, API tokens, multi-factor authentication (MFA) metadata, access tokens, and SSH public keys.
- Billing & Payment Information: Payment method details, transaction identifiers, and payment processor receipt tokens (card details are processed directly via PCI-DSS compliant gateways).
2.2. Service & Operational Data (WhatsApp Business API & Messaging)
When clients leverage our WhatsApp Business API integration platform:
- Communication Metadata: Phone numbers of senders/recipients, delivery timestamps, read receipts, message status codes, API endpoint response times, and failure logs.
- Message Content (Payloads): Text strings, media attachments, template IDs, and button response payloads. (Note: Payloads transmitted through our automated relays are stored only temporarily for queue processing, webhook forwarding, and error debugging, subject to client retention policies.)
- Meta/WhatsApp Account Data: WhatsApp Business Account (WABA) IDs, Phone Number IDs, Meta Business Manager IDs, and template submission logs.
2.3. Custom Web & Software Engineering Project Data
In custom development engagements, we may process technical specifications, database schemas, repository commits, test user datasets, API mocks, and deployment logs provided under strict non-disclosure and service agreements.
2.4. Automatically Collected Technical Data
- IP addresses, browser type, operating system version, and device identifiers.
- System usage logs, error stack traces, API rate limit counters, latency metrics, and session activity via cookies/local storage.
3. Legal Bases for Data Processing
| Legal Basis | Applied Purpose / Activity |
|---|---|
| Contractual Necessity | Executing software development agreements, routing WhatsApp messages, managing user authentication, and handling invoicing. |
| Legitimate Interests | Platform security, API abuse monitoring, bug resolution, infrastructure optimization, and legal defense. |
| Consent | Marketing newsletters, optional third-party telemetry, and non-essential analytical cookies. |
| Legal & Regulatory Compliance | Tax accounting, responding to lawful government/judicial orders, and audit trails. |
4. Roles: Data Controller vs. Data Processor
- When We Act as a Data Controller: We determine the purposes and means of processing personal data relating to our direct clients, website visitors, sales leads, and administrative account holders.
- When We Act as a Data Processor: When clients use our SaaS platform or WhatsApp Business API integration to message their own end-users or customers, the client is the Data Controller and we act strictly as a Data Processor. We process such end-user data solely in accordance with the client's documented instructions and the applicable Data Processing Agreement (DPA).
5. WhatsApp Business API & Third-Party Disclosures
Our WhatsApp Business API services interface directly with infrastructure provided by Meta Platforms, Inc. / WhatsApp LLC. By deploying our WhatsApp Business API connector, you acknowledge and agree that:
- Message routing between telecommunication networks and our API gateways complies with Meta’s Business Terms of Service and WhatsApp Business Messaging Policies.
- Data transmitted over WhatsApp is processed through Meta servers in accordance with Meta’s privacy and technical frameworks.
- Clients are strictly responsible for obtaining verifiable opt-in consent from their end-users prior to initiating business-initiated WhatsApp conversations.
6. Data Sharing & Sub-Processors
We do not sell, rent, or trade your personal data. We disclose data only to trusted sub-processors and third parties strictly necessary for operational delivery:
- Cloud & Hosting Infrastructure: Cloud server providers (e.g., AWS, Google Cloud, DigitalOcean) for application hosting, encrypted database storage, and edge CDN routing.
- Messaging Infrastructure: Meta / WhatsApp for WhatsApp messaging delivery; licensed CPaaS providers for fallback SMS or voice protocols.
- Payment Gateways: PCI-DSS compliant payment processors (e.g., Stripe, Razorpay, PayPal).
- Monitoring & Diagnostics: Logging and application monitoring tools (e.g., Sentry, Datadog) utilizing pseudonymized log streams.
- Legal & Regulatory Authorities: Where required by valid subpoenas, court orders, or applicable statutory mandates.
7. International Data Transfers
Because our SaaS infrastructure and sub-processors operate globally, your information may be transferred to and processed in countries other than your country of residence. When transferring data across borders, we implement recognized cross-border transfer mechanisms, including Standard Contractual Clauses (SCCs), robust technical encryption standards, and adequate organizational safeguards.
8. Data Security Standards
We implement industry-standard technical and organizational security measures to protect data:
- Encryption: TLS 1.3 / HTTPS for all data in transit; AES-256 bit encryption for data at rest (databases, storage buckets, backups).
- Access Controls: Role-Based Access Control (RBAC), mandatory Multi-Factor Authentication (MFA), and least-privilege administrative access policies.
- Monitoring & Isolation: Continuous network intrusion detection, automated vulnerability scanning, and containerized tenant isolation.
- Code Security: Secure SDLC pipelines, static analysis scanning (SAST), automated dependency auditing, and strict secret management.
9. Data Retention & Erasure
We retain data only as long as necessary to fulfill contractual commitments and legal compliance:
- Account & Invoicing Records: Retained for the duration of the active account plus up to 7 years to satisfy statutory tax/accounting laws.
- API Transit Logs & Webhook Payloads: Retained for a rolling period (default 15–90 days, configurable per enterprise tier) for error diagnostics and auditability, after which they are purged.
- Custom Development Source Code & Databases: Archived or returned to the client upon contract completion and termination of warranty periods, per mutual NDA terms.
10. Your Data Rights
Subject to your local data protection jurisdiction (such as GDPR, UK GDPR, CCPA/CPRA, India DPDP Act), you may have the right to:
- Access & Portability: Request copies of your personal data in a structured, machine-readable format.
- Rectification: Request correction of inaccurate, incomplete, or outdated data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data where retention is no longer legally justified.
- Restriction & Objection: Restrict or object to certain processing activities, including direct marketing.
- Withdraw Consent: Revoke consent previously granted at any time without retroactive invalidation.
To exercise these rights, submit a formal request to our Data Protection Officer at the contact details provided below.
11. Cookies & Tracking Technologies
We use essential cookies for session handling and security. Non-essential cookies (analytical and performance tracking) are deployed only in accordance with your browser preferences or cookie banner consent. You can disable cookies through your browser settings, though certain SaaS dashboard capabilities may be degraded.
12. Policy Updates
We may periodically revise this Privacy Policy to reflect modifications in our software architecture, regulatory standards, or business capabilities. When material revisions occur, we will notify registered account holders via email or an in-platform dashboard announcement prior to the effective date.
13. Contact & Grievance Officer
For inquiries, privacy concerns, or data rights requests, contact our designated privacy department:
- Company Name: NEW AGE TECHNOLOGY
- Attn: Data Protection Officer / Grievance Officer
- Email: support@newagetechnology.co.in
- Physical Address: 5, Mangalam Vihar D-A Ext., Benad Road, Macheda, Jaipur, Rajasthan - 302013
New Age Technology Legal Governance
Signed & Approved by Yash Kumar Jha